RNNR Privacy Policy
Version 2026-09-28.1 · Prepared 28 September 2026
This notice applies when this version is published. It describes the current Service and how information is handled when token features are enabled.
In this document
1 Who this notice covers
This notice describes information handled through RNNR at https://rnnr.fun, including The Undercity, wallet login, balances, lobbies, challenges and support. The controller is 1v1me.me, Inc., a Delaware company. Contact [email protected] with privacy questions or requests. RNNR and Memecoin Arcade are product names.
The Service supports free practice and, when enabled, Solana token play. Its operator controls the game vault and its internal records. Your personal wallet's private key and seed phrase remain with you; do not send them to us. A public wallet address is not necessarily anonymous: it can be connected to public transactions, your activity and other identifying information.
2 Information we handle
Wallet and session information includes your public wallet address, a signed login message and signature used to verify control, session-token hashes, site origin and session expiry. A verified wallet session is not proof of your real-world identity. The game does not require a player email address or account password in the current build.
Token and gameplay records include the exact mint, prepared and signed transfer details, public transaction signatures, finalized receipts, game balances, entries, queue and lobby activity, game inputs or checkpoints, outcomes, reserve accounting and leaderboard scores. These records let us settle games, reconcile custody and recover interrupted transactions. They are not all public blockchain records; some are held in the Service database.
Acceptance records include the authenticated wallet, site origin, server time, policy versions, document fingerprints and the affirmation displayed when you agree. We record an age and eligibility declaration, not a date of birth or a verified identity document.
Network and technical information can include IP address, request path, request time, browser or protocol information, response status and error information processed by our hosting and security providers. The application uses wallet and IP-derived hashes for rate limits and holds short-lived connection information. Hashing an IP address does not necessarily anonymize it.
Device storage includes essential login cookies and local browser preferences such as wallet-provider choice, sound, controls, reduced motion and whether practice was completed. Support information includes contact details, public addresses, screenshots, transaction references and the contents of messages you choose to send. Avoid including information about other people or secrets in a report.
We collect information from you, your browser or wallet, your use of the Service, public blockchains and service providers involved in operating it. We do not currently require routine government-ID, biometric or payment-card collection. Any later identity-verification service would need its own notice before collection; this policy does not claim that KYC is already implemented.
3 Why we use it
We use information to authenticate wallet sessions, operate the game and queues, prepare and verify transfers, account for custody, settle results, show history and challenges, remember preferences and provide support. We also use necessary information to enforce fair play and access controls, investigate errors or abuse, secure the Service, meet legal obligations and handle disputes or rights requests.
Where data-protection law requires a legal basis, operating features you request and maintaining relevant records may be necessary to perform the agreement with you; security, troubleshooting and service integrity may rely on legitimate interests subject to your rights; specific records may be required by law. Optional processing that requires consent will be separately offered. Acknowledging this policy is not blanket consent to advertising or every future use.
4 Who receives information
Authorized operators and support personnel can access records needed for their work. The deployed service uses OVHcloud hosting and Cloudflare network and security services. When token features are enabled, the configured Solana RPC provider receives blockchain queries and transactions, including public addresses and signed transaction data. Wallet providers process the connection and signing requests you initiate under their own terms. Email and backup providers may process information when used for support or preserving records.
We may disclose information to professional advisers and authorities where reasonably necessary for legal obligations, lawful requests, protection of rights or investigation of fraud. In a business transfer, relevant records may transfer with the Service subject to applicable safeguards and notice requirements. We limit service providers' permitted use of personal information through applicable arrangements and implement safeguards required by law.
We do not sell personal information, share it for cross-context behavioral advertising or use it to build targeted-advertising profiles in the current Service. We do not embed third-party advertising or behavioral analytics in this build. Public blockchain publication, service processing and material you choose to share are distinct from an advertising-data sale.
5 Public results and public blockchains
Solana transactions and addresses are publicly visible and may remain accessible indefinitely through third parties. We cannot erase or edit the blockchain. Anyone may correlate addresses and transactions with other information.
The public Guard Hunter board shows generated wallet-derived aliases and game scores rather than full wallet addresses. An alias is not a guarantee of anonymity. Lobby participants and permitted viewers may see identifiers, activity and results made available by the relevant game interface. The server retains the underlying wallet association for accounting and scoring.
Using a share button, publishing a result card, posting a clip or opening an external social service can disclose the content you select. Review it before sharing. Other people may retain or redistribute public material. External sites, explorers, wallet apps, token-launch platforms and social networks apply their own privacy practices.
6 Cookies and browser controls
The player session cookie, rnnr_player, authenticates a wallet session for up to 12 hours. A separate operator session cookie, rnnr_owner, can last up to 30 minutes. Cookies are used for authentication and security, not advertising. Logout invalidates the relevant session; clearing browser storage or blocking cookies may also require another sign-in. Expired records may remain until application cleanup runs.
Local storage saves your selected wallet app, gameplay preferences, practice-completion preference, transfer request identifiers used for recovery, and limited run diagnostics. It stays in your browser until you or the browser removes it. It is not proof of policy acceptance; the authoritative acceptance record is on the server. Clearing storage does not delete a server balance or a blockchain record.
The current build has no optional advertising or analytics cookies to enable. We do not treat a Global Privacy Control signal as consent to sell or share data. Because we do neither for advertising, there is no such processing to switch off in this build. Essential operation and security continue. If optional tracking is introduced, the notice and any legally required consent or opt-out controls must be updated first. Legacy Do Not Track settings do not disable essential authentication.
7 Retention and deletion
We retain information for the purposes described, taking account of outstanding balances, unresolved transfers, security investigations, disputes and applicable recordkeeping requirements. Financial and acceptance records may need to remain after you stop playing so that obligations and the accepted agreement can be established. We do not promise immediate deletion of all data when a browser session ends.
Authentication and rate-limit records have operational expiry or cleanup rules. Application rate-limit cleanup targets old windows, but does not promise a fixed deletion time for every row. Local preferences remain until cleared. Backup copies may retain information for their rotation period and need controlled deletion or expiry; we must avoid restoring deleted data to ordinary use unnecessarily. This release does not yet implement automatic deletion of all historic gameplay, ledger or acceptance records.
We assess retention by data category and legal or operational need, rather than keeping unrelated information simply because storage is available. Contact [email protected] to request deletion or information about records held for your wallet. We may retain records that are necessary to resolve funds owed, establish or defend claims, prevent fraud or comply with law, and will explain applicable limits. Blockchain records and copies independently held by others are outside our deletion control.
8 Your rights and requests
Depending on your location and which laws apply, you may request access or a copy, correction, deletion, portability, restriction of processing, or object to certain uses. Where consent is the legal basis, you may withdraw it without undoing prior lawful processing. You may also complain to the relevant privacy regulator.
Where the California Consumer Privacy Act applies, rights include knowing the categories and specific information collected and disclosed, correction, deletion, opting out of sale or sharing, and limiting certain uses of sensitive information, subject to lawful exceptions. We do not sell or share information for behavioral advertising and do not use sensitive information to infer personal characteristics for such advertising. We do not discriminate for exercising applicable privacy rights. This notice does not assume the Service meets every statute's business-coverage threshold.
Send requests to [email protected]. We may verify control of the relevant wallet through a free, clearly described message signature or other proportionate evidence. We never need a seed phrase, private key, wallet password or token payment to process a privacy request. Do not email these secrets. An authorized agent may provide appropriate proof of authority; we may also verify the underlying request. We will respond within applicable statutory deadlines and explain a denial and any applicable appeal route. You may request reconsideration at the same address or contact your regulator.
9 International processing
Hosting, network security, blockchain infrastructure and support can process information in different countries, including the United States. Their laws may differ from those where you live. Where applicable law requires transfer safeguards, the operator must use an appropriate mechanism and make relevant information available on request. Merely accepting a website notice does not substitute for required safeguards.
10 Automated game decisions
Software automatically handles authentication checks, eligibility settings, admission limits, game simulation, settlement calculations, leaderboards and some abuse controls. These functions can affect the outcome of a run or access to a feature. We do not claim that every decision is made by a human. Contact support with the lobby or transfer reference to request review of a suspected error. If applicable law gives additional rights concerning a significant automated decision, those rights continue to apply. Requesting review does not itself reverse a saved outcome.
11 Security and children
We use measures including access restrictions, protected server secrets, HTTPS, signature verification and accounting checks to reduce risk. No system is completely secure. You should protect your wallet and device, review signatures and report suspected compromise. Support staff will not ask for your personal wallet's secrets.
The Service is intended for adults aged 18 or older and any higher age required for a particular feature. We do not knowingly solicit personal information from children. If you believe a child has provided information, contact [email protected] so we can investigate and remove or restrict it as required by law. An age checkbox is a declaration, not verified age assurance.
12 Changes and contact
We publish a dated version and explain material changes. Where required, new uses need additional notice, consent or another lawful basis before they begin. A new privacy notice is acknowledged alongside new Terms before new token deposits or entries; this is separate from marketing consent. Requests concerning old records and existing available withdrawals remain accessible.
For this policy, rights requests or support, email [email protected]. You may also write to 1v1me.me, Inc., 453 S Spring St., Suite 400, Los Angeles, CA 90013.